Re: Given access to edit active directory



If you let someone log into a domain controller then there is a good chance they can bypass any security you put into place. Have the local admins load the admin pack tools on their PCs and just delegate access to them to manage users.


--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



pbuzzby@xxxxxxxxx wrote:
Hi

We are tighing up permission on our office network and want to remove
the admin permissions to a lot of server.

What i need to do is allow an Actiove directory group to login to the
domain controller and ONLY have access to the magae active directory
panel and then only allow them to add new users.

Is this possible?

Also is it possibale to alow this group to modify current group and
users permissions without them being allowed to assign anyone as a
domain admin?


Thanks in advance

.



Relevant Pages

  • Weird Permissions Problem
    ... When logging into a DOMAIN CONTROLLER as what we refer to ... them rights to. ... Example in one container we created a OU ADMIN ... WHY are the permissions not working properly apparently? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unable To Add DC
    ... 232070 When you run Dcpromo.exe to create a replica domain controller, ... > computer account to a domain controller "Access is denied" ... > something to do with the permissions in active directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Creating a Power Users Group where none exists
    ... permissions need to be changed to allow a regular user to run their application. ... admin users, but still not recommended on a domain controller. ...
    (microsoft.public.win2000.security)
  • Re: Admin Rights SharePoint
    ... Admin permissions (if you are talking about admin permissions when logging ... on to Active Directory) mean full access to everything unless someone at ... if you lowered the permissions for the SharePoint site for the one user I ...
    (microsoft.public.windows.server.sbs)
  • Re: Creating a Power Users Group where none exists
    ... permissions need to be changed to allow a regular user to run their application. ... admin users, but still not recommended on a domain controller. ...
    (microsoft.public.win2000.security)